Vulnerability Development mailing list archives

Re: Information Leak Bug Discovered in Netscape Mail!


From: Markus Kern <markus-kern () gmx net>
Date: Thu, 22 Nov 2001 16:23:17 +0100


We at GOBBLES Research have discovered an insecure condition in Netscape
mail which could assist an attacker in gaining important information
regarding the accounts of those who use the client.

"Netscape 'document.referrer' User Information Disclosure Vulnerability"

http://www.securityfocus.com/bid/2824

"Originally discovered and posted to Bugtraq by Rop Gonggrijp <rop () itsx com>
on March 28, 1998. Rediscovered by 3APA3A <3APA3A () SECURITY NNOV RU> on
May 30, 2001 and posted to Bugtraq on June 5, 2001."

Also advisories with a little less noise would be really cool...

--
Markus Kern


Current thread: